1. Acceptance of Terms
By registering for or using CertiSecure ("Service"), operated by WebVanta Innovations, you agree to be bound by these Terms of Service. If you do not agree, you must immediately discontinue use of the platform.
2. 90-Day (3-Month) Subscription Cycles & Auto-Reversion
All paid subscription plans (Pro Tier and NGO Bulk Tier) operate on a 90-Day (3-Month) Subscription Cycle from the date of purchase.
Upon completion of 90 days (3 months) from your purchase timestamp:
- Your subscription cycle automatically ends and your account is moved back to the Free Starter Tier (`subscription_plan_id = 'free'`).
- Your monthly allowance resets to the standard Free Plan quota (25 certificates/month).
- Pro & NGO benefits are locked until a new 3-month subscription is purchased.
3. Unused Certificate Credit Vault & Claim Policy
CertiSecure enforces a strict zero-waste credit policy:
- Automatic Rollover: Whenever a 3-month plan cycle ends or resets, any unused, ungenerated certificates are automatically saved into your account's Unused Credit Rollover Vault.
- Claiming Unused Credits: You can visit your Claim Credits Page at any time to claim your unused credits. Claimed credits are added directly to your active quota as bonus certificates.
- No Expiration on Claimed Vaults: Unused credits saved in your rollover vault remain stored until explicitly claimed by you.
4. 24-Hour DevSecOps Data Purge Lifecycle
To protect privacy and minimize server storage liabilities, all uploaded CSV files, temporary template renders, and generated certificate ZIP archives are permanently hard-deleted 24 hours after batch processing. Users are solely responsible for downloading their generated ZIP packages within this 24-hour window.
5. Password Complexity & Security Controls
All user and administrator accounts must enforce strict password complexity standards:
- Minimum length of 8 characters.
- At least 1 Uppercase letter (A-Z), 1 Lowercase letter (a-z), 1 Number (0-9), and 1 Special Character (!@#$%^&*).
- Password reset links expire strictly after 10 minutes and are limited to 3 request attempts per 24 hours per email address.
- Password reset requests are restricted exclusively to standard user accounts (`role = 'user'`). Admin accounts must be managed through secure backend controls.
6. Two-Factor Authentication (2FA) & Trusted Devices
Login requests from new or unrecognized devices trigger a mandatory 6-digit SHA-256 hashed 2FA OTP sent to your registered email address. OTP codes expire in 10 minutes. Selecting "Trust this device for 30 days" sets an encrypted device token (`certisecure_device_token`) that bypasses 2FA challenges on that specific browser for 30 days.
7. Acceptable Use Policy
You agree not to use CertiSecure to generate fraudulent academic, legal, or professional credentials, or attempt to bypass security rate limits. Violations will result in immediate permanent account termination without refund.
8. Contact & Legal Notices
For questions regarding these Terms of Service, contact our DevSecOps team at Support Inquiry Portal.